From owner-freebsd-apache@FreeBSD.ORG Thu Sep 8 11:55:04 2005 Return-Path: X-Original-To: freebsd-apache@freebsd.org Delivered-To: freebsd-apache@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DDF7316A41F; Thu, 8 Sep 2005 11:55:04 +0000 (GMT) (envelope-from simon@eddie.nitro.dk) Received: from eddie.nitro.dk (port324.ds1-khk.adsl.cybercity.dk [212.242.113.79]) by mx1.FreeBSD.org (Postfix) with ESMTP id 759D143D48; Thu, 8 Sep 2005 11:55:04 +0000 (GMT) (envelope-from simon@eddie.nitro.dk) Received: by eddie.nitro.dk (Postfix, from userid 1000) id 9375611A31A; Thu, 8 Sep 2005 13:55:02 +0200 (CEST) Date: Thu, 8 Sep 2005 13:55:02 +0200 From: "Simon L. Nielsen" To: Huynh Van Chung Message-ID: <20050908115502.GB78024@eddie.nitro.dk> References: <009c01c5b46b$764b16a0$c6012685@postitec11> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="xHFwDpU9dbj6ez1V" Content-Disposition: inline In-Reply-To: <009c01c5b46b$764b16a0$c6012685@postitec11> User-Agent: Mutt/1.5.10i Cc: freebsd-apache@freebsd.org, security@freebsd.org Subject: Re: About apache vulnerability CAN-2005-2728 X-BeenThere: freebsd-apache@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Support of apache-related ports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 08 Sep 2005 11:55:05 -0000 --xHFwDpU9dbj6ez1V Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2005.09.08 20:50:08 +0900, Huynh Van Chung wrote: > I see the CAN-2005-2728 is not yet patched to apache ports(last updated= =20 > with CAN-2005-2088) It is patched in the apache2 port version 2.0.54_3 (check the references). The commit message just didn't mention that CVE name, since it was not known to us at the time. --=20 Simon L. Nielsen FreeBSD Security Team --xHFwDpU9dbj6ez1V Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQFDICaVh9pcDSc1mlERAsqAAKDJYMV8LoNGVpewE1fGf6ia6zO+lgCePyDZ zdIWJTRnNY+mOAmGN+4BKlY= =v20R -----END PGP SIGNATURE----- --xHFwDpU9dbj6ez1V--